Senior Information Security Manager

Careers and Enterprise Company
London, UK
2 days ago
Apply on www.adzuna.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Part-time / full-time
Experience level
Expert
Experience required
3 years minimum
Compensation
£60,000.0 - £65,000.0
Working hours
Regular working hours

Tech stack

Cyber Security Information Security Management Microsoft Office Information Technology

Job description

Working Arrangements: This role can be home-based, with occasional attendance at the London office required, or performed on a hybrid basis (depending on your location). This is a permanent position (37.5 hours per week) although we are open to excellent applicants seeking part-time work (i.e. 4 days a week, 0.80 FTE), The Careers & Enterprise Company, a non-profit organisation with a social purpose, is looking for a knowledgeable and committed Senior Information Security Manager to join its small Compliance Team. Reporting to the Head of Compliance (CEC’s Data Protection Officer), you will lead CEC’s ISO 27001-certified information security management system, strengthen processes, and help shape policy. In this role, you will play a key part in ensuring information risk is managed effectively, overseeing security governance and standards, conducting audits and monitoring, and ensuring policies and processes continue to improve. Your work will be essential in providing assurance that the young people’s data entrusted to CEC is secure.

You may already be leading information security governance in a smaller organisation, or you may have built strong experience as a key member of a larger information security or governance team.

We are seeking a candidate with broad experience across information security and governance, including most of the following: identifying and assessing information risk, managing controls, carrying out internal and third-party audits, improving processes, developing training and guidance for staff, managing and reviewing incidents, and contributing to policy development.

Because CEC works with children’s data and provides digital tools for careers education, we are especially interested in candidates who are motivated by social purpose who understand the importance of security governance in this context. An appreciation of data protection, tech ethics, and safeguarding will be important in helping you thrive here. Technical skills and experience matter, but so do your values.

We are passionate about helping young people take their best next step, and keeping their information safe is fundamental to that mission. This is a fast-moving environment, so you will need to be comfortable working through ambiguity, building strong partnerships across teams, finding practical solutions, and confidently raising significant risks when needed.

The key responsibilities of this role are to oversee information security standards by managing and continually improving CEC’s ISO 27001-certified Information Security Management System, leading business continuity management for information and technology risks, and supporting the organisation’s development of a proportionate quality management approach, including work towards ISO 9001 certification.

Requirements

You may already be leading information security governance in a smaller organisation, or you may have built strong experience as a key member of a larger information security or governance team. We are looking for someone with at least three years’ experience, ideally five, working in an ISO 27001-certified environment. A CISSP or similar professional or academic qualification is preferred, and an understanding of quality management, or a willingness to develop it, would be an advantage.

  • A minimum of 3 years of work experience in an information security governance role within an ISO 27001 certified environment
  • ISO 27001 Lead Implementer or Lead Auditor certification
  • CISSP, or a degree or equivalent level 6 or above qualification with an information security focus, or computer science or similar including relevant security modules

Skills and core competencies:

  • Good knowledge of current information security threats and best practices for information security management and governance
  • Delivery focused with excellent organisational skills and attention to detail
  • Capable of building and maintaining strong working relationships across teams and working through ambiguity
  • Motivated to find practical solutions, yet willing to escalate significant risk
  • Confident user of Microsoft tools and comfortable developing skills for use of new technologies

Please note that a basic DBS check is required for this role before any offer of employment can be confirmed.

About the company

We are the national body for careers education in England, delivering support to schools and colleges to deliver modern, 21st century careers education.

The Careers & Enterprise Company (CEC) is a great place to work. We operate within a fast-paced and collaborative environment. We are brought together by one thing: our passion to ensure young people get the best possible start in life and are supported to find their best next step.

Do you want to be part of a mission-driven team focused on transforming young people’s lives? If so, we’d love to hear from you!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:12 min

Empowering enterprise engineering through open source program offices

Cédric Gégout Cédric Gégout +4 · World Congress 2026 Europe

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all